Vulnerabilities > Openstack > High

DATE CVE VULNERABILITY TITLE RISK
2016-02-03 CVE-2015-7546 Insufficiently Protected Credentials vulnerability in multiple products
The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keystonemiddleware (formerly python-keystoneclient) before 1.5.4 (Kilo) and Liberty before 2.3.3 does not properly invalidate authorization tokens when using the PKI or PKIZ token providers, which allows remote authenticated users to bypass intended access restrictions and gain access to cloud resources by manipulating byte fields within a revoked token.
network
high complexity
openstack oracle CWE-522
7.5
2016-01-29 CVE-2016-0738 Resource Management Errors vulnerability in Openstack Swift
OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.
network
low complexity
openstack CWE-399
7.5
2016-01-29 CVE-2016-0737 Resource Management Errors vulnerability in Openstack Swift
OpenStack Object Storage (Swift) before 2.4.0 does not properly close client connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.
network
low complexity
openstack CWE-399
7.5
2016-01-13 CVE-2015-8466 Improper Input Validation vulnerability in multiple products
Swift3 before 1.9 allows remote attackers to conduct replay attacks via an Authorization request that lacks a Date header.
network
high complexity
fedoraproject openstack CWE-20
7.4